Cross-Agent Authorization Bypass in AgenticMail Allowed Task Enumeration
CVE-2026-57494
7.1HIGH
What is CVE-2026-57494?
The vulnerability in AgenticMail's API allows a low-privileged authenticated agent to enumerate another agent's tasks by using specific API endpoints. By supplying the target agent's name, an attacker can retrieve sensitive task information, including task IDs and payloads. This compromises the security model as the task IDs, intended to be confidential, can be exploited to manipulate tasks assigned to different agents. The issue arises due to the ability of authenticated agents to discover agent names through the account directory API. Version 0.9.64 of AgenticMail includes a fix to address this vulnerability.
Affected Version(s)
@agenticmail/api < 0.9.64
